Courseiva
easyMultiple Choice

CISSP Practice Question: Is conducting a security assessment of a new web…

An organization is conducting a security assessment of a new web application. Which testing technique would best identify cross-site scripting (XSS) vulnerabilities?

⚠ Common exam trap

Candidates often confuse SAST and DAST. Remember that SAST requires access to the source code (white-box) and is performed early in the SDLC, whereas DAST is performed on a running application (black-box) without requiring source code access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic application security testing (DAST)

Dynamic Application Security Testing (DAST) is a black-box testing methodology that inspects a running application from the outside in. Because the assessment is conducted without access to the source code (black-box), DAST is the primary method used to find vulnerabilities like XSS and SQL injection by actively injecting payloads into input fields and analyzing the application's runtime responses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manual code review

    Why it's wrong here

    While thorough for specific code sections, manual code review is inherently time-consuming and prone to human oversight, especially in large or complex applications. It struggles to identify vulnerabilities that manifest only during runtime interaction, such as intricate cross-site scripting (XSS) payloads or complex injection logic that requires dynamic execution to trigger. Its effectiveness is limited by the reviewer's expertise and the sheer volume of code.

  • ✗

    Static application security testing (SAST)

    Why it's wrong here

    Static Application Security Testing (SAST) tools analyze an application's source code, bytecode, or binaries without executing the program. While effective at finding common coding errors and some architectural flaws, SAST often struggles to detect vulnerabilities like XSS that depend on user input, server-side processing, and client-side rendering during actual runtime. It lacks the context of how data flows and interacts dynamically, leading to potential misses for injection points that only manifest during live execution.

  • ✗

    Interactive application security testing (IAST)

    Why it's wrong here

    Interactive Application Security Testing (IAST) operates by instrumenting the application's code and observing its behavior from *within* the running environment, combining aspects of SAST and DAST. While it offers excellent visibility into data flow and vulnerability context, IAST typically requires access to the application's internal components or source code for instrumentation. This makes it less suitable for black-box, external security assessments where only the exposed interfaces are available, and the focus is on simulating real-world attacker interactions without internal access.

  • ✓

    Dynamic application security testing (DAST)

    Why this is correct

    Dynamic Application Security Testing (DAST) actively tests the running application from an external perspective, simulating real-world attacks against the deployed environment. By interacting with the application's exposed interfaces (like a browser or API client), DAST can effectively identify runtime vulnerabilities such as XSS, SQL injection, and broken authentication by observing the application's responses to malicious inputs. This black-box approach accurately reflects an attacker's view and confirms actual exploitability, making it highly effective for web application security assessments.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.